2026 CVE Vulnerabilities
70,493 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2597 | HIGH | 7.5 | 0.3% | Feb 27, 2026 | Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_by... |
| CVE-2026-27773 | MEDIUM | 5.3 | 0.3% | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-27772 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona... |
| CVE-2026-27767 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona... |
| CVE-2026-27652 | HIGH | 7.5 | 0.3% | Feb 27, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to... |
| CVE-2026-25945 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen... |
| CVE-2026-25851 | CRITICAL | 9.8 | 0.6% | Feb 27, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona... |
| CVE-2026-25778 | HIGH | 7.5 | 0.3% | Feb 27, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to... |
| CVE-2026-25711 | HIGH | 7.5 | 0.3% | Feb 27, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to... |
| CVE-2026-25114 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen... |
| CVE-2026-25113 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen... |
| CVE-2026-24731 | CRITICAL | 9.8 | 0.6% | Feb 27, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona... |
| CVE-2026-22890 | MEDIUM | 5.3 | 0.3% | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-20895 | HIGH | 7.5 | 0.4% | Feb 27, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to... |
| CVE-2026-20792 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen... |
| CVE-2026-20791 | HIGH | 7.5 | 0.3% | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-20781 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona... |
| CVE-2026-20733 | MEDIUM | 5.3 | 0.3% | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-1585 | HIGH | 8.4 | 0.1% | Feb 27, 2026 | An unquoted Windows service executable path vulnerability in IJ Scan Utility for Windows versions 1.1.2 through 1.5.0 ma... |
| CVE-2026-3268 | MEDIUM | 4.3 | 0.2% | Feb 26, 2026 | A vulnerability was detected in psi-probe PSI Probe up to 5.3.0. The affected element is an unknown function of the file... |
| CVE-2026-3265 | HIGH | 8.8 | 0.5% | Feb 26, 2026 | A vulnerability was identified in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. This affects an unk... |
| CVE-2026-3264 | HIGH | 8.8 | 0.4% | Feb 26, 2026 | A vulnerability was determined in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. Affected by this is... |
| CVE-2026-28280 | HIGH | 8.7 | 0.2% | Feb 26, 2026 | osctrl is an osquery management solution. Prior to version 0.5.0, a stored cross-site scripting (XSS) vulnerability exis... |
| CVE-2026-28279 | HIGH | 8.4 | 0.9% | Feb 26, 2026 | osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `o... |
| CVE-2026-28276 | HIGH | 7.5 | 0.3% | Feb 26, 2026 | Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions p... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now